This Global Privacy Policy describes the privacy-related terms supplied in the Vmemoo Legal & Compliance Pack for Vmemoo Limited, trading as Vmemoo.
1. Introduction and how this Policy works
This Global Privacy Policy ("Policy") describes how Vmemoo Limited, trading as Vmemoo ("Vmemoo", "we", "us" or "our"), collects, uses, shares and protects your personal information when you use Vmemoo's website and mobile applications (together, the "Service"). This Policy works alongside our Terms of Service, Community Guidelines, Memorial Policy, Copyright Policy and any purchase-specific terms. By using the Service, you confirm that you have read and agree to this Policy. If you do not agree, do not use the Service. Nothing in this Policy excludes rights that cannot lawfully be excluded, including mandatory consumer rights.
2. Information we collect
We collect information you provide directly to us, information we collect automatically, and information we obtain from third parties.
Information you provide may include account and profile information, memorial information, communications and payment information. Information collected automatically may include usage data, device information, imprecise location information, and cookies and similar technologies. We may receive information about you from publicly available databases, social media platforms if you link your account, or other partners.
3. How we use your information
We use the information we collect to operate, secure, moderate, improve and provide the Service; communicate with you; ensure safety and security; comply with applicable laws and enforce our terms; manage memorials; and support research and development. We do not currently use advertising SDKs or cross-context behavioural advertising. We do not make solely automated decisions producing legal or similarly significant effects unless disclosed and lawfully supported.
4. Sensitive information
Memorial content may incidentally reveal religion, health, ethnicity, sexual orientation, political views or other sensitive information about living people. Do not upload sensitive information about another living person without a lawful basis and appropriate authority. Where Vmemoo intentionally processes special-category data under EU/UK law, it will identify an Article 9 condition, apply additional controls and obtain explicit consent where that is the appropriate condition.
5. Public content and visibility
Information set to public may be viewed, copied or reshare by others and may be indexed by search engines if that feature is enabled. Privacy settings reduce platform visibility but cannot guarantee that a recipient will not capture or disclose content. The interface must clearly show the selected audience before publication.
6. Sharing and recipients
We disclose information only as reasonably necessary to:
- Other users and the public, according to the feature and visibility selected.
- Hosting, database, authentication, storage, content delivery, security, analytics, crash reporting, messaging, push notification, customer-support and payment providers acting under contract.
- Professional advisers, auditors, insurers and corporate transaction participants subject to confidentiality and lawful safeguards.
- Authorities or affected parties where disclosure is legally required or reasonably necessary to protect rights, safety and security, subject to review of the request.
7. Service-provider register
Vmemoo uses service providers only for defined operational purposes and under appropriate contractual safeguards. The principal provider categories at the effective date are: Emergent for application development, deployment and managed infrastructure; MongoDB or an equivalent contracted database host for account, memorial and interaction records; Expo, Apple Push Notification Service and Firebase Cloud Messaging for mobile builds and push delivery; Apple and Google for app distribution, authentication where selected, in-app purchases and store transaction records; and contracted email, security, logging, content-delivery and support providers enabled in production. These providers may process account identifiers, device and push tokens, content, transaction references, diagnostics and security logs as needed for their function. Processing may occur in the EEA, United Kingdom, United States or another country in which a contracted provider operates, using the transfer safeguards described below. Vmemoo maintains an internal, current subprocessor register and will update this Policy before adding advertising or materially different tracking technology.
8. International transfers
Vmemoo is intended to operate internationally. Where personal data is transferred from the EEA, United Kingdom or another jurisdiction that restricts international transfers, we will use a lawful mechanism such as an adequacy decision, approved standard contractual clauses, the UK Addendum or International Data Transfer Agreement, or another valid safeguard. We will assess relevant destination-country risks and apply supplementary technical and organisational measures where required. A copy or summary of relevant safeguards may be requested at privacy@vmemoo.com.
9. Retention
We retain personal information only for as long as needed for the stated purposes, legal compliance, safety and dispute resolution.
- Account and profile data: while the account is active; deletion or irreversible anonymisation from active systems within 30 days after a verified deletion request, subject to stated exceptions.
- User Content: until deleted by an authorised user, transferred with a memorial, removed following a valid request, or handled through the account-deletion process.
- Backups: isolated from ordinary use after deletion and expired within 90 days; restored only for disaster recovery and then re-subjected to the deletion record.
- Transaction and tax records: 7 years, or any longer period required by applicable accounting or tax law.
- Safety and moderation records: up to 3 years, or longer while a legal claim, investigation, serious repeat-abuse risk or preservation duty remains active.
- Security logs: 12 months unless needed for an active investigation.
- Verification copies: deleted promptly after verification unless preservation is legally necessary.
10. Security and incident response
These are Vmemoo's published retention periods. Where a provider backup cannot delete one record immediately, it remains isolated from ordinary use and expires through the provider's documented backup cycle.
We use risk-appropriate administrative, technical and physical safeguards, expected to include access controls, least privilege, encryption in transit, protected credential storage, logging, patching, backups, vendor review and incident response. No system is completely secure. Where a breach triggers notification duties, Vmemoo will notify regulators and affected individuals within applicable legal deadlines.
11. Your choices and rights
Depending on location, you may have rights to access, know, correct, delete, restrict or object to processing, receive portable data, withdraw consent, opt out of certain sale/sharing/targeted-advertising uses, appeal a refusal, and complain to a regulator. You may submit a request through Settings > Request my data, Settings > Delete account, https://vmemoo.com/privacy-request or privacy@vmemoo.com. We will verify identity proportionately and may request authorised-agent documentation. We will not discriminate against you for exercising a right. EEA users may complain to the Irish Data Protection Commission or their local supervisory authority. UK users may complain to the Information Commissioner's Office. Canadian users may contact the Office of the Privacy Commissioner of Canada or an applicable provincial regulator. Australian users may contact the Australian Information Commissioner after first giving Vmemoo a reasonable opportunity to respond. New Zealand users may contact the Office of the Privacy Commissioner. US residents may contact the relevant state attorney general or privacy regulator where applicable.
12. Account deletion
Account deletion is available in the app and through https://vmemoo.com/account-deletion. We will explain whether a memorial will be deleted, retained with another administrator, anonymised or restricted. We may retain limited information required for law, fraud prevention, security, dispute resolution or enforcement, but will not keep it for unrelated use. App deletion from a device does not delete an account.
13. Adults-only service and information about minors
Vmemoo accounts are restricted to people aged 18 and older. We do not knowingly permit minors to hold accounts. If we learn that a minor created an account, we will restrict and delete it after appropriate review. Contact privacy@vmemoo.com to report a suspected minor account. Adults may upload appropriate memorial content that includes a minor only where they have lawful authority and respect the minor's privacy, safety, dignity and best interests. We may remove, blur, restrict or de-index such content following a credible request, even where the uploader objects.
14. Regional US disclosures
During the preceding 12 months, Vmemoo expects to collect the categories described above, which may correspond to identifiers, customer records, commercial information, internet or electronic activity, approximate geolocation, audiovisual information, inferences and user-submitted sensitive information. Sources, purposes and recipients are described in Sections 2, 3 and 6. We do not sell or share these categories for cross-context behavioural advertising. We do not knowingly sell or share personal information of people under 18. If Vmemoo later reaches a state-law applicability threshold or changes these practices, required notices, opt-outs and contracts must be implemented before the change.
15. Canadian, Australian and New Zealand supplements
Vmemoo will designate a person accountable for privacy, use information for identified and reasonable purposes, provide access and correction mechanisms, and investigate complaints. Canadian users may challenge compliance through privacy@vmemoo.com. Australian complaints will be acknowledged and handled under a documented complaint process. New Zealand users may request access and correction and will be informed if a correction is not made and of any available statement-of-correction process.
16. Changes and contact
We will post updates with a revision date and provide additional notice for material changes.
Controller: Vmemoo Limited, Ireland. Privacy contact: privacy@vmemoo.com. Vmemoo Limited has not appointed a separate Data Protection Officer at the effective date. Privacy matters are handled by the company through the privacy contact above.
